Brazil's INSS data breach leaks information of millions of beneficiaries
A security failure in Dataprev, the state-owned company that processes Brazil's federal data, caused a breach of the Instituto Nacional do Seguro Social (INSS) databases on 22 April. The incident was reported to the Agência Nacional de Proteção de Dados (ANPD) the same day, and containment measures were applied immediately.
The INSS confirmed that roughly 97 % of the exposed records belong to individuals who are deceased, while about 50,000 records relate to living beneficiaries lacking death information. Internal sources suggest the breach may have affected up to two million people. The institute reported no signs of fraudulent benefit claims or loan applications linked to the leak and highlighted the continued use of additional safeguards such as facial‑recognition biometrics.
This breach follows earlier incidents involving INSS data, including a 2024 exposure that led to the temporary suspension of the Sistema Único de Informações de Benefícios (Suibe) and raised concerns over long‑standing access‑control weaknesses.